mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 13:49:24 -04:00
qcacld-3.0: Fix invalid bss descriptor length check
bss_descriptor->length is calculated as:
bss_desc->length = ie_length + sizeof(*bss_desc) -
sizeof(bss_desc->len)
In csr_parse_bss_description_ies(), the bss_desc length is
validated as below to return failure if ie_length is 0:
=> (bss_desc->length - sizeof(bss_desc->len)) <= ieFields_offset
Since the bss_desc->length already has the sizeof(bss_desc->len)
subtracted while it was populated.
So this could return failure, if the SSID IE length is less than
or equal to 4.
To avoid this, change the failure condition as below:
(bss_desc->length <= (ieFields_offset - sizeof(bss_desc->len))
Change-Id: Ib0af8e967c26ff0ca9a3b8c44107be4e80378e01
CRs-Fixed: 3022657
This commit is contained in:
parent
86dc23d58e
commit
8079aa438f
1 changed files with 6 additions and 4 deletions
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright (c) 2011-2020 The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2011-2021 The Linux Foundation. All rights reserved.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for
|
||||
* any purpose with or without fee is hereby granted, provided that the
|
||||
|
|
@ -1389,9 +1389,11 @@ QDF_STATUS csr_parse_bss_description_ies(struct mac_context *mac_ctx,
|
|||
int ieLen;
|
||||
|
||||
ieFields_offset = GET_FIELD_OFFSET(struct bss_description, ieFields);
|
||||
if (!bss_desc->length ||
|
||||
(bss_desc->length - sizeof(bss_desc->length) <= ieFields_offset))
|
||||
if (bss_desc->length <= (ieFields_offset - sizeof(bss_desc->length))) {
|
||||
sme_err_rl("Invalid bss_desc IES: len:%d ie_fields_offset:%d",
|
||||
bss_desc->length, ieFields_offset);
|
||||
return status;
|
||||
}
|
||||
|
||||
ieLen = (int)(bss_desc->length + sizeof(bss_desc->length) -
|
||||
ieFields_offset);
|
||||
|
|
@ -1400,7 +1402,7 @@ QDF_STATUS csr_parse_bss_description_ies(struct mac_context *mac_ctx,
|
|||
if (!DOT11F_FAILED(dot11f_unpack_beacon_i_es
|
||||
(mac_ctx, (uint8_t *)bss_desc->ieFields,
|
||||
ieLen, pIEStruct, false)))
|
||||
status = QDF_STATUS_SUCCESS;
|
||||
status = QDF_STATUS_SUCCESS;
|
||||
}
|
||||
|
||||
return status;
|
||||
|
|
|
|||
Loading…
Reference in a new issue